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f t^£gg©&Kgt£<$ o r Bg^-^HiC <fc ») Bg-Sfft L , 

L. 10 

*-S75-f>F*S*£jsSU Ch*&|(#£IIC<:jgQ 
XL. 

±iang^{ta^rt§^^t?tt«(c^t--5±iB^i^© i t 

££Ott$R£*l1^llg^&II 7- *£L r &A L. 
(d) JtJBMHttt. ±E&HII{C»|£-ril««i€:tto 
tawstc <fc 0 ±I3H|# f b&Hrt3£$tf L 20 

xmmznz* ±E8aws«:»«T4«}i©»n 
[m#*2 ] n*a i ©*Hsaefl»c**»-c. ±ie 

Xf-^(d) KjtSoT, JHt^A*. £{f bfc±IBBi-Sf 

a£#±iBWaigtc cfc o r *g $ nr c > a c t *mm 
l. wftfisnrtSsfe^trtiMRiyxh^R-rs^f 
yy(d-o) <t. jjaaswai. e»©B»<tsairts*« 

*K??ft^&C££5ifSTSX7 9 7'(d-l) 
tf. 30 
3 ] fg^JM 1 XB 2 ©*HB5£&ffi{C*5t> 

(a) B ±IEJa:^©*3!ii*0o-CI,>S*y%4j*"rS^ 
_|JBI»#{tSSIrt8 4 iJB * LT ± 

SBfttWc «fc •JSSL-r-SXf- ^ 7*£^, ±13X7 v 7(d 
-l) B±IB*W©&Ilr--£rt>6±8B£y£7>!§fL. -£ 
©£ Mie»0^0-C*5*?:tSt5^f 7 7££ 

[ mm 4 ] n*gi i xb 2 (vm^mkum cc *u » 

T, ±iBX7 9 7"(b)«±fB77W'>Kg:g£i*x.fcg: 40 

M££Sf t#$© n x h yxhti -c&*r s 

^5^, ±13X7 9 7' CO B±i3&I£gyxh 

7'%£tj. 

[1U&B5 ] M$!H 1 XB2 ©*f8SWrffitc*5l,» 

r, ±13x7 * ^(©tt±Eion^s©im-fi[**^* 

[IMSR 6 ] Ift&I 1 XB 2 ©S^BSI^tcfcU 
t, ±ibxt- ? ^(a){ctet»r±iatS:M#B±iBBiIffia 
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Kfc^TiEftjiaaUbKSaif*- * £&i3£-e±i3* 

[W*S7 ) n^qi 1 XB2©*TJBK5Srffi{c48(,> 
r. ±IBXr9 7-(a)«±IBSM^C^-r^^^©W 

«^*fiXL, ±iaa:ii»4ft«:±8E^i«eatc3jg-r 

S X t- 9 7£$&. ±I3X x 9 7' Cb) B±lBg^7>tc>Pf 

-rs±eajR#©»*©iEatt*tt3iE-*-s^^3 
tf. 

nmm&) H»9i<om^WKnmicii^x. ±§b 

*#L. *n-en©»f5«fHS«ltBStt4«»HSK:j: 

o *a $ n . ±eie« tt»±ieatt©^ttiitf«iiK tc 

0. ±IBXr 9 7(c) r£8S!s&tt±E8SI? : -*4± 
IB v U - X©-ffi©#f5(*lt*SSgtC£{i L , ±I3X 7 

9 ?(<9B±iBiiiregtB#-eti-eti#s<§* sa^iaa 

dt»««*^'j -x*{c*^a^aL. «&&©»*& 
ate j: k> nzmm^n z x ? » 7*^tf . 

[»«319 3 IH*3H©«^jfi:II*ffi{C*jl»T. ±§3 

m^mtmk(Dftmmiims.*mL, -en-en© 
»ft«tt#taiBStt ssshacc i o «a s ti. ±e» 
aMtt±E«8»©»iwiigt«fta{c»a l r ^n-en7> 
tWi'SiSii Lrfdfj^renrteo, ±13x79 7*(o 

•CSSM^BilBS^T 1 - $ ££-C©±fB7}fjt»it^$! 
■tcaSftL. ±f3Xf-9 7-(d) B±iaRH*itB*J**i 

-eft#d* sa^asptc j: 15 ±E»«fi«e«*flBt>r 

±f3Bi^tSMF'9^ ; Jr)3iJ^^jI#MaLT«-fi1a^f _ 
* *4JS*L. ^fr&ibtc 1 o©»|M(itt#S6if (cjRft. 

Lr±i3SHf*9S=&»'5Xf i 9 ^%^tr. 
[ 11*31 1 0 ] 8 XB 9 ©**«*#£ tc*j I » 

t. JJB1X^Wn». ±IB»ft*9t^B©2«±©^ 

a-c*-E>. 

i &f 32 amtsr^tt s n fcm^-SM ->x 7 a ic 

&±IB&H^£HB, 

S^rtS?: *lt^iS©^BB^-C B§^< b L T Bt^^fcfiM 
±l3Bg#{bg:^rtg?r±l3SLS!ccmSLLrmiMaX ; Sr^ 

±K«a#*SB*> h %m l fc±Ba»i«s«©±gBBif «i 

aX«:^-TS77-Y > Kg^^lBSLgfc©!^!^ 
I^^T±IBBf^^bfi:MrtS ; 5r^tfti$RCC^T.5±f3 i ga 



n?- $ 4 i/csataaa^aa-j-a^at *a*. 
.teaaastau. 

±12 ^7 4 > K SS ^SM^g^ff t -5#S 4 Z$ 
*. 

£f#*a^ss4, 

m>m 1 2 ] 1 1 ©i^si^^fAKtei,* 
r> jjaaaaaattltc. ±ei*afb8:aW84a& 
aatca-r s±E«a#»«*ttBT &*aa*g*a 

S*a*. *©«S#a«aSS«:J:3aEtcatt-ra 

4±e8Ht- * *±K»tHi«B^aa l . ±E*it 

3aa»&JJE&aaaa *» h *a 1/ _tf B&M r - * 20 
[»*a 1 3 ] M«a 1 1 ©a^SSIf Xf-ACCfcl* 

r. ±Kaa*8BttKKJJBttaa:fc«:»TS183il# 
a« *ftfiJLhcra#(^^«-r *«ai«»«ffifiss 

Eajsaxav *©saaa« £$aEt 

aS*a#. *©aHK:£«TSi±E77-f>Ka« 

[SH^fl 1 4 ] 1 1 ©a^Hi'X^Atcfcl* 

T . ±eaif-*aBK±e*8*»g ©8EK£te? s 

4 s±tesM*sa^ b fcjjaaaf 8 - z © v x 

214*30. 

[»3jaS 1 5 ] S&#Jil 4©SflSM'>Xf i A(c*Jl» 

r. ±E&a«£a«, ±K«*#©#*i*ii-9T(,»a* 40 
y*4fiJE-r5*^»4S4. ±Esi^b£sw4±E 
* y*aas L/-c±ebi a<fc&9iOT8tatriiNR*£iar 
saisst. ±E&H'jx ^©^tasir-^^ia 

5 c 4 ic <fc 0 g #©&igr - if #±E&SI 'J x h tc * 5 
[i*^ 1 6 ] 1 1 ©S^aM^x^Aicte^ 

0. JJ2»ffi«tt±ffiatt©»ttattaaaK:»«L-C 50 
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ttt^ftattaaaib-cwos-c&tiTfco. &±e 

SH^gfctJbE&Ily 1 - $ * UBf 'J - X©-4SS|©# 

aattaaatcaau ±ia^t4mit^a«-?-*T? t ^ 

aaa<D±KatmttaKBt<: *ttt &±ea 
[ss*5 1 7 ] m*m 1 1 ©mT-aM->xf-A«:teii 

t. ±eatW«Btt*h*ft*&S*It*K:j:»)aa 

Sftsaa©»aatta«B**i/. ±i2a««B±ia 
aa©^K*it^atc^f ii l- r ^ti-en^tttMea 4 

LTgfl^-ce.JvCfc'h &±EaaaaBtt±E«HI 
^-ffc^TOjJBatfcJMt^SSatci^U ±E±E 

»twiitt««Bi«n-enao ^-c 6tifc±E»»««f 
^Pa-f-^ttoSL/. ^tbik&tc 1 o©_kE#ijrJ6it 

«tta{ca*a-wni»*wi/"c*j»). ±e*»a«>fc 

1 ^©±E#ffc*Bt#ilB«*tf>e>tl/c£T©±E«# 

* *a4wai L-c±E«arts*»s«aa-f» 

[i*3fcai8] 8**311 6X« 1 7©m : f-SM^Xf 

atfaaaaaitfs. 

[i»«a 1 9 ] a&©&s£g£SB4 . &±e&aaa 
a 4 egaaft-c&a $ n/css^a 4 , s±iBsm 
^^a 4 j»iag mimz-cmm $ *i fc«st«Ka* stra 

!93ilF«9S«:Mta«a©fiHa-CB#{bU. ^{bS^ 

±renw<b!swrts*atri««*±iBatt«: «fc 0 asi t 

f^S4. 

±EBg^{bSMrtS{C>Ft-r^±IBg}l^©S«4±EBt 

#<b«airts*atra««rA*ur. ±Eaaa©»« 
*©»«aas©aa«:aar 4 i±E«a*©»* 4 

iEBi^fbSMrt^^rStfa^R^iS^f 1 - * 4 L-CJtft 

aaa^aars^at. 

±Eaaaaa*>6aaofcaa'jx hoituciBoa 



(4) 

5 

£Hrtf. 

m*m2 o ] n*m 1 9©an«tBt«:*ji»r. m 

Si . _bEBg#<b&Hrt§i±E2 l/T±Elt 

y* h*o#tasif t -** > e>±SB3'^ i feaai/ t *©* 

IiC«afiB-C%RSti^*94HaEB&. &±Ett9K 
B&K&feES&ftlSTffiRS ttfc*i+£gB*^tf m 

Si. 

JbE*8*I« ©tftBfc£1W & i &±EB££ttB*> 
6B«Ofc±Ei83it? t -*©y*F*f&*U ±E&H 20 

±E&H»tc*tiw 4«*«»c «t o ±ew 

[»3$B 2 2 ] n«392 1 ©ftft^BB^ti^ftH 

acSBsracctoBashs. «»©j";-xBfc3ft 

fc»ft»ltBBB**U JjettB£tt±E£R©#tt 

-c^ircfco. s±es»B»fi*&a&*ifc±E«:B 30 

f : - * tt±IB-> 'J - X©-4S©^t$!*t1-^«g{c J: "5 * 
^E#K»B»4m>r±Elfc#fb!!8Krt3*£frt» 

[1**52 3 3 n*g2 1 ©»it«*aiB*n-enji 
0 'tii § ti s»tt©aftfttt«£B«ff 

L . ±Effc«»«±El»*©»ttBftB«B L/ T 

»ttB£Btt£r©i:E8aiB«B*>e>±Ea»?*- * 
£gftu too 6*afcjjE»ike?sa*ffli»T±E 

0. *«>ft«>fc 1 o©Jja&»*tt#»B«:i3*#tta 
OT* 0 , ±K**>»»fc 1 oOJtE»» 

[38*92 4 ] 11*52 2XB 2 3 ©Btt#BSK*S 

i»r. ±E»»a#«aasB. ±e»miHHtto2 50 
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w±©^*^i?>/c»t(±*i8W^«:-rn«a#pjei^H<i 
[m*b 2 5 1 m®<D%m$imt . &±ebbbb 

B£E£9{IBtftft3ftfcffSB£B£. &±E£B 
B8B£BE«9fiH?Sflk3WdMt«£B*£&tt 
* BBi/* r Atcfc *&I{:g«g©Ma#im* n > t 

(b) a»*»£U 

(c) ±EW#ftaairtS«:*tf1f«*±Ea«rClJBLL, 

riwaaxfcmst/, 

(d) _hEW«HI£©»««:£JiRU 

(e) JbE»«m^tf*©»«%a$S^3SB^2aS 
U 

tzmmmx.ictit &±Et as© ^ -y > F*«*>e.± 
Eatt©B»*R9»i»T±EflH*{tfiBrtS**t>« 
*jc*t-ra±E«ffi#©»«*#*>. 

(h) JbEjESttOtttElc^tt-r * £±E*NWISBKrtS 
*£tt«»£±E«iiB©»:S«:fi»7 ! - * i LT*lt 
BBB^aiBU 

[tt$B2 6 ] tt$B2 5©Efia»ft{C*Jl>-C. 

Z??7t. ±EH#<baBrtS±±E*y*B*SLr 
JJBB*<fcBBrtB*Btt11l«*^-r*a?- ? 7'i£ 
B*. ±EXf^7'(i) ttJbEBBBBBfr&BBl/fc 

Cf«*52 7] a^©SM#^Bi. &±K8jK#&! 
■ iE«aflK8-C««3nfc«a««Bi. #±ES^ 

^ t5M->x f AKfcW €»*f+«^g©Ma#IB?r a > f 

a- * -cuff t z>wy=> AZnm btcmmfcvb -> 
« i ±E*<wb««rts* stsm mm *> ^a*©§ 

ZtZAJlLZ ±E«a#©S« ^t^EL-, 

(b) ±E*a#»*©tttE«:^tt-rS4ft±Ea3ll#* 
B^ l/te JJEtt*? 8 - * © y * h x h i 
br^fiXb, *©ja:ii'jxh4Ssi«*Jri'-b^niffiK 

(c) ±E^BS««:*fi6T*«F«a«:«fc ")±E»#{brtS 



ot ^m^<o^mn^n . 
(d) ±sm^titci$m^icm^xmmmrm 
mzmntz. 

[mxrnz 8 3 it$«2 7©E»ii(t«:*ji,>r. ±ia 
niHWiitttft-eixRa *«t*c <c o sas . 
MR©*/ 'j ftfc»ft*traH«**o. ±e 

±Ei/y-X©-«(O»ftjiai-#«B«:J:05Wil/. -t io 

Bftmmmm t» t ±ehw{ t&nrtg **t»f««* 
f8©±E»»*it#ii»c tew sjjB^tta-t jaatc «t 

[iMtfl 2 9 ] M&I2 7 ©E»«f*«:*tl»T . ±E 

jtfHMtK»«*ve , tiji& sust^tc «t o «as nss 
&©#ifc*gt#iat£ m o . ±EtHB«tt±E»K©# 
iS!*it#iiB{c»woT*ti*n»ft«afat otsio 

ST6hTte<3, ±EX;f ?7 - Cc) B£#f&*it#gg 20 
tcj: 0 ^T©±efiB«ftB* ^E&Mt 1 - £ 

taairtSta^ftfflOTa-^itJiaif-jfiSfiSo. **i 

£^ft&ftfclo©±EMx*ft*ISgCt£9. ±12^ 

©i*»fc i o©±ia^ti(mit^»gt*^A6n/c^-c© 

±E«#$IBf r - * S!iaOT±ES3SlrtS4 
ffSXf-^^WOTC^. 
[»«3I3 0 ] 1**92 8X«2 9©EMi^(*CC*j^ 
T. ±EXf^7 - Cc) t*±E»«E«tt«ttB©. 2fcLL 

©**»©fc»fe(±*iibflE*Tnt<a^pi«ja:ini^ 30 
[|6W©I¥8B&i89n 

[0 00 1] 

[$MB©K*S8«»»] C©*MBtt. BiWUfS/^f- 

^jt^Ocfc^i-rsm^^x^A. ^tmsmmj-j- 

oy^AEflMlfttcHrs. 
[0 00 2] 

©«!«*> 6 ssac***©^ $ ft/ess ( 1 xb 2 « 40 

±) ©ft»*iWRO. *©iW?fe*4iaH-#K:4;t. £ 
JfiOTB. jftjfiWa*K*JWSS«ffl#©*|}©#Jt 

fc. StXftStt. Sll««i«ROA:4R}fl««-nUim 
«. E#. «b3. JSBfci'T**. 
[000 3] feBg&XK. &X*&8Xrt$©*t]£& 
ttSJKT* . fflA©Sfflfc*KN-J-*:75 A^-J&^f 
£©&CilOTt,>£©T\ m-T^a-^CATVIfOjR^lSj 
iifiT©7>^- f-iElSSItcfijffl-ctS. 50 
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[000 4] JtSUiMtctei^T. 3c£&teB««HI*fT 
5KB. &g«©&g«>z:*&lf t 8:aiftS©fiEtt(c# 
5»«rtS©«»©l»±a^-C*$. cn6©KS 

^^rs^&iOT. ? j i> $ ^m&zm^tcn 1 !-®. 

M^*5»H$nTte"3. m«. Atsushi Fuiioka, T 
atsuaki Okamoto, Kazuo Ohta: "A practical secretvo 
tinq scheme for larqe scale elections" , in Advanc 
es in Crvptoloqv-AUSCRYPT'92, Lecture Notes in Com 
puter Science 718, Sprinqer-Verlaq, Berlin, pp.244 
-251(1393) . B^#?Fajl!I&HJ6-19943 (1994^1X3 

28B&H) r«-fjgao5F*6Rt;*itj fc>j*3frc(,»4. 
[0005] c©st*ffir«. s^v.^tam^gv, * 

^k,CCj:0Bt^bOTBi#Xx 1 <!:O. CttiCT^-O F 
»* *» * fc*©W«ai £ O T xi *a« r, tc «fc 0 SSL O 
rlMfflR**ffi«t/. iJ«ffliXft«:Sa!*©»«s,* 

Kl-^^taiSv, ©jEStt*SHOfc«. UMBaXe, 

-r*. s^v.BBfl^aXctcjt-rs^^^^Fs^d, 

*>6H»X)cKStfSJWWra#A©»«y 1 **J*>. C 

^Xx, # s**a# a cc<fc 9 *s 3*va» a c ± «rb 

OT. lf#:*x, **©**-«&»*-*. fUES^KS 

#©b§ #Xx, **aes tin s^rt^v, ©us 

tl^tt*it#C{C*fOTSfl«:* OUTS. Ult^CB 

v ( *a^o, ctu&niwa. 

[000 6] 

[»WaWKi*OJ:5£-rSBW» L*»0tt#6. C©# 
STB. ftsg^v, #&S8S^K^ SttildaSMBfr 
?.a»©e#Xx,3&JSE»StiA:C<b*«KO. §tk,£j| 
tt^CKiUff-rsCiA^-C^O. IP*>. «9iS©fi.l 
ffi14©<St^>XfAr*S„ 

[0 00 7] C©^©iJ!)B, -i'^-^mc 
i4<si$istm. Sfc. *it#©^IE-?=ti#g 

fflOfcH?r*it^«:^S'i:>S©^i\ ffift^m^SM^ 
X f- ±.RUZ<Dl5m*ffl3k-t Z C t tc h h . 
[0 00 8] 

[^gi%s?»-rs/cto©^S] cowprctt. 

S^rtS^ftlt^C^HTBt^fbO. MtC-?-©Bi^{b 

t»rtS4a«-caai/TW«ifflx*fffisoT. *©w 

«HR«:f« *«W T iWMHl#K:aSflrJ- * . 9¥V9 
#tt. ^U0Sn)it»**ffli,>T!SJII*©iEStt*HKO 

Z7v-il> F»«**SOI*K:aS*)jEr. J9:M^Bh!T^ 
aX{c»TS^^> K»«*»6SUtt©IB»*B*)l»l f > 

Te#ittaairts«:jt-rsa**a«©»«t»«** 

ft. Bf^{bS^rt§£«(clSMr-$£OT£tt^K:ii 



m «*ijB^iFa#«: i ixm% $ nx i»a c i^nis l. 
ft#«*{b«©-»*«8u «it*±jtfet/<B-je 10 

OffiB^S*ai'3HlfJ:5«:L.-CfeJ:l». 

[0009] coAwcAtia. *#<i&aratt&x 

[ooio] cct, fl^tftBIUhfftsftftOTfe 
0, StHfB. BH(©te«>K|IBBiyH*^a«*fT45 

[ooi i ] MHrttm i-rn«. *-ti6*w>f s 20 

CiKiOW^MbSnfcSPrtSiBBll-r A 
WPUSrtrHtc. sa^EMSttfijercfcaciB. * 
#{b$ftTl>St^rtS£a*Sa#©3££i£3ft:W 

-c^-rci^-c^s. int. aaissE-j-ssst*©--* 

K*&8ifi&&b1tt Lrfe. £*fe IX B-S»©» 

[0012] *fc. #ttsnftj|»t#(cB. Bi^bsn 
/cSsirtStfilss©-?, c©ia£fe£*feu<B-g 
»©«&##«* i/ttt»a»ff>j. ^©F^(c-e©ji*ig 30 

[ 0 0 1 3 1 etc. jmt#^*"Ctt< -jeKansaTa 

#. fel/<». HH^©tt*3&J^nIffiitt-5-Cfe. EL 

<H*ff«*fffc5ci*sr#a©t\ c©*sci*»* 

W14©K^^f-A-C*5il-i*. 
[0014] 

[&BJ!© HiS©ff28 ] JJTF© HSfcFiJ©t&Bj§ Kfct >T B. 
t9»©W i L-TRteWflHMCfcW &£HfC C ©ail* £ 40 
fflUd*£Koi>-ctBBB-f wai/teJ:9CC. C© 

mi mm 

t?*S. TAOSISv, (i=i,-,T) ©^g (ttSEtS 

ginf^) 100 b. a#sa#A©iis (B^essis 

Sinf^) 200 i. £fcSlH-«C©=gg (SlSt^St 
nf*) 300 i, -e-n-eniE«jifi?S4oo . Rvm&%m 
im 500 <&*r b x mm. $ nt c » * . &aegv, a««»<f 50 
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s§4oo zmbxmmmmgAicm&zmstzm-SK. 
b, t©»a«:ae#3W(fr*s^*^-}-am«tiia. 

«*«&gv,XttBW01t*ia £ttflQLT:i*<If £fe© 
£U &lB«iHIB500 £iIUCftit:§CK:1t$R£j£fi 

■r b. *©w mcmztmztt m v & i» t © 

i-T*. *fc. JHt#CB8aErtS©-R (SUVXh 
ScmHStyXr) *&HU &K#B£JI. CttKT 

t>-teW5imv$>z>ttz>. H3(ciai©S5i^xf-A 
tcfcwssawiaiioo ©flwtw*. ^4tcjMp«s# 

gg2oo ©tiliSt*!*. a5K*i+$gS300 ©fltaMI& 
?p U H 6 (C C (D&WO&Mi/ X r- A (Cte W i ii(i-> - 
4->X#l£^ir„ ®2Al,cmmWm%Att^LX 
l>5«*t#';^h24QAS:. H2B(Cfi3H*B*^*.ft:lS: 
-J X h 240B£ . H 2 C C jWJSJE L fc&Hfg 

t, *»oHfffr©J8;iiyx h320A^. S2DCcHit&© 

®M ') X h 320A* , 12E «#Hgt 'Ml- 320B^t?iJ^-T 
[0015] fclTTB. #tc8HK#V, A<94t«a#A 

[0 0 16] CCf, «T©W!l«C»BSti4E£** 

tsbxmt. 

[001 73 x = i c (v,k,c) : $fflmc<ov§mm® 

(x : Bg^X. v : S^rt^. K< : ftBt#©&Htt) 
v = Pc(x,k 5C ) :^l+^C©a^{bMS[ (ksc :l!St* 
©^«a) 

s = a, (e) : gH^V, ©S^^BQft < s : *g. 
e : SSmt&MP)®) 

e = ?,(s) :&H^V f ©•^tc^-T&ttiEnft 

d = a. (e) : mmmm% a <d7?<<> fm^aam 

(d : 75 4 >F»S) 

z = ?. (v) : ii^«S^A©S«tC»T?»fellIMI!i 
(y :»*. z :&l£fflffi) 
e = co A (z,r) :»a,PB» (r : SL^t) 
y = 5 A (d, r) : £L»fiS^I^5feB8lfe ( d : 75 A > FS 
«) 

cct, *st*c©»i#fbMa€cia^bia»PcBfii 
*]©&HiiB#*s:-c«effl3ti-ci>4fe©-c*o. *it 

^CB^SIk.c **MSK:^fU £HSk, t ?:8it 
{C^HL."Ct>Sfe©i-r4. S»#* J 77-f>K 
g«4S*T^>lg«:S«>Pt»©^ v ■fe-i?m£SL»r? 
75 4>K-TS (754> FS«©/c©©pfteS*-r 
4) fcft©W.B»fl>.(z,r)i, SWBS5o/c75 4>F 

^ts§A©§«y^gxotn-ro SLttn^^ntt^ 

.(d,r)B. ji^ i tII^A^ffiffl-r^77 4> F»Sntt 

0. jftjftSEntf. £'j»w«:9i*sfe©-c*a. c©^^ 

ft»*H»«C^l>-CB. ^l*tfRSAIIt^©Bf#{bH» 
ifS^bMifc* 5 *^ (Ronald Ri vest, Adi Shamir, Leo 
nard Adleman: "A method for obtaining digital sig 
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natures and public-keycryptosvstems" , Ccmmunicati 
ons of the ACM, Vol.21, No.2, pp.l20-126(Feb. , 197 

8», as i?m%*g#?ztcib<Dms&mkbx<o 

mk&&hm\><D^&tt.r>^xmmkt. David Chaum 
: "Security without identification : Transaction 
systems to make big brother obsolete " , Communic 

ations ofthe ACM, Vol.28, No. 10, pp. 1030-1044 (Oc 

t., i985)tciejiEsnrc^„ 

[ 0 0 1 8 ] 0 3 K^-TSHif «Sioo B#©J: *) ictt 
, l&mv,tmft2t\Xi<>Z. £tc, ggioo 

\mm «cff}#$4ii. Bg^tnuo b&h^v, vmiR 
uc&mpmv,* (ccvtemz.imm%zaii\) nit 

m. ^m^.mmmm,i:^L. ^©sL&t.B 

x, | t.^tij^T S„ z.^SMffliffiiPfACitc-r 
S. fl»8£Si20 »SL»r,«:l64-rs. JSSL2§130 B 20 
^5^>F»8©fcJ6©tt*HIiLr. ftiLHfte, = co 
a (z, , r, )K «t 0 S^fflto £SLSfc n -C«SL bfWSXe, 
*4JSWS. »«f^RSSi40 Bfr^SXatcWLSS^ 
v l ©k©T£>-2>t££7jrf fcitxpg&s, = a,(e, ,1ft) 
,s, ,Ift> Bi3tgffg|5l90 rt^il 
{181400 «r^oraHMHiMi200 KiSHSfi*. a 

fis§4oo ic&zmmmzm.iw to&mit. mm 

a^8S200 AS K»«d,#»IS*i5*-C*i 

[0019] £Lftj£ft|$£8l50 «S$£a3&X200 30 
fr6i£§fi2l5i90 (C«t<5S<tL/fc^7^> r*S«d,*>6 
SUttr, *ttoTa»fiS#BSH»y, = 5. (d, ,r, )tcj: 0 
SUu&»£l&*b. y.^a^fflffiz.fc^Taii^'lS* 
A©g££bTfS&„ g«&3£3Pl60 ttttSHftz, = C 

a (v, ) sWisa-r 4*>**aE-rs c tic <t o y , jwEsr* 

4*«ttE-rS. if <z< , y^Bg^f 1 - fibres 
(fgRiso ft>6fttHf£ft300 fc&fi;*fts. 'jx H&S 

§Pl70 B*tt«Slg300 (C7i'*XbriSS<ISI5l80 CC 
«fc 9 « tc&M V X h 320AS&2T Z> . 
[002 0304 (Cot-TOW a#SB200 BW*g© 40 
ftMUMKiD, JlJ^felEttShteWWJ^ H240A (02 
A) t. ^©^^-^x/clg^I^lJIt^Ift 
iit?fi*#vx h240B (02 B) i*Kf$**;fc»©ie 

tt»240 i, bfcliSIJtt^Ift ##fl^ 

jE.^tp*mmtL* (s, )*»BSfi-r**>Kj: 

TSg«^Sg|5220 t . I3fc»ISS«etta5240 ©Br 
X h f¥A.V260& . mFSaJIXe, CC*t? S 79 A > KS« d 50 
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. = a. (e, )*4Ji!c-r4*«f¥(iSS230i. 
©x-£©i*g{i£fT5ii£{sS|5250 tZGLX^Z. 
[0 02 1 ] B5K:5vr«fc5ec. mit*^g3oo B&8 
^SSgioo fr^gmSHm icj:t)%m bfc&Hx-^z 
, , y,>*©&Hffliffiz,£SPt&#A©S«y 1 K»bt* 
hhsccyo ^ffior 2l = Ca(v.) #$3±-f6fr£& 

SrsC<b«cj:0»*y,«r«fflET5**«aEa53io i. 
fil'MF ftj$tt370 K «fc *) Sir- f <z, , y, >tca b 
S-Stq.^ttttT&H'JX F 320A (02 C) tCflD*, 

-rai5tt.gi532o i. istmm&z, = x, it,*6ie#*x,4 
»«r a^gtsu35o i. *tt^©^«gik S{ ^,ta 

■^H»Pc {C«fciJx l 4B»bT:v l = p c (x ) ,k lc ) ?ra^ 

*ftH340 ££?tf S/c. IB1SSI3320 tC«}#$nT 
i^iS:^ ^ r 320A©iib#-^q (c>Pttc;-r a^Mr- ^ 
&c0 2 D«c^-r<t 5 (cfs^^n/ci^mrtifv, train* 

So *lt^B02 EtC^-Ti^CC^ffl (CNft; h=l, 

2,... ) ©f#MSfec#K(h=i,2,... ) itm'J^hJimi. 

bri5itsi532o cc^jfsh*. ®my*h32(Atnm') 

X h 320B©F>9SB^figP380 ^lUTJ^t/fca 

[0 02 2 ] felT. C©»-©3WIW(CfcWSail©^ 
H ; Sr06?r#Mb-C|jiBj-r^ o 

Xf77 - Sl : SM^v, HE. SM^^gloo (03) 
J: 0 am©«(i^)i(T© J: 9 5. 
[ 0 0 2 3 ] X 7" 7" 51-1 : S^#v, B. !35f l*lgv, 
iB^bSno r*lt#c©&Mfllk,« iBg^bMiS^ 

Xi = €c (v, , k, c ) 

*fPfi6T S. Mtc. * #&&8xii fC <t 0 * ^t, 
b , 2HSS112 tc «fc 0 x, i MS b r S^fflfJS 
z, =x, I t, 

^^t.BmBSLSfC^O, tSM#v,©**sg 
#© t ©T A -5 C £ £*uo T t» 6 . 
[ 0 0 2 4 ] X f 9 7S1-2 : SM^V, B. SLft&fflS 
120 4ffll>-CSL»r,*4fiRL. ^SLSl30 ^ffll^Tz,?: 
r.CC.fc^gJSLb-CHlitoaX 
e, = co A (Zi . r, ) 

[ 0 0 2 5 ] X f- ^si-3 : &X#v, B. ««fNSS 
s, = a, (e,. Ift) 

=&fffiSb. r-*<e ( , s, . ID, > %SIS(I8I5190 *>e>jS 
^«S^g200 4C3M(i1-S„ 

Xf-;7S2: jS^II^S200 (04) B. §15 
$ ft/cWf g£ v, 4 *©BW0t»«Ift ©H8&£0 2 A K 
^-rJc^tcWti^'JX f240A (02A) 4br^*Wb 

tc)t>(mm%>)Z H240B (02 B) £WbTOS. 
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fcaM#©«B5v t £&K0Tcfct>©T*>*ittf8si#«v ( 

*n«^siJtt$8iD, sn^xf A4L-a> 

r*i*>-*«:ft»r *» < . WTOttMTttftiWv, ©$ 
JSMMRiO, 'J X h 240B (H 2 B ) tc»*iibc 

tits. uaHMWBS^jft-cB. aaw;xKo*K 

[ 0 0 2 6 ] X f -7 7'S2-l : BfflHW A tt. jg^^ 10 
^WttgT&SCiS:. W«l#';xh240A(S2A) (C 
■8MMII* ***S*>S3&>*!9ai«l«EB»2io tcfcOH 
^TttfSfS,, tL&Wfttt. aW9#A(2»IB«iE 

[ 0 0 2 7 ] X f » 7'S2-2 : S«*9# A tt. C ft« 

UfflGty* h240B (H2 B) {CIO, 

a. feu. id, *wc*s5ti-ri>fc&e>tf. a^ss 
«A«-saMiLr*i2^m§-rs„ 20 

[0 0 2 8 ] Xf? 7*S2-3: ID, #$7c#£iA$ftT 
JSWhtf. a^gS^Att. S«^2H220 
s, 4e, , ID,*i^3C 
(e, , ID,) = C.Cs.) 

*jfBfiT**«ttE1-S. tU £tttt6tt\ a^ifa^ 
Att e,*»«fffl»230 Jcai/T. WSd, 
d, = a A (e,) 

•T 4 ifttc. &K# >J X h ffi«8B260 K«fc 0 iet^gP240 
l*i©iBi# 'J X Y 240B (02 B) fclBK&V, ©ID, £iE 30 

[ 0 0 2 9 ] X f * 7S2-4 : fi3Rgft*7Sl a^fr 

g^Att. fa3iW'jxh240Bi8aw«*^a-r*. & 

fl«©jl«B*/M/ r jWMBI#sai2oo ©fetg.gP240 

rt©SM# 'J X h 240BJC7 ? -fe X nJteT$) 5 C 4 £S*0 

L/-cfc< 0 c©yx h'vori-fe^sa, m«7* 
se&yx h240B©^JiRifttap^a^Kg2oo 
t<fcl>. 

X f 7 7' S 3 : ttl&v, tt . SM^ilgioO (S3) 
4. 

[ 0 0 3 0 ] Xf » 7S3-1 : Sigigv, tt, d,ir, £SL 
j»tt»l»*gi50 KA^L/r. £Mfflil8z,CC*hrsg:g 

y, =5.(4, r, ) 

[0 03 1 ] Xf v 7"S3-2 : &H#V, (J, so 
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160 *ffli»r. v,*«a*«s*A©»*r*sci* 

z, = £.(y.) 

*»Bfca-rs*>K j: otters, to. *£t&r*-3fc«t 

6, &M#V,ttf-£<e, . d, ^tfI" C i(C «fc 0 . a^ 
SSgA©*iE£i§g-f£. 

[ 0 0 3 2 ] X f 9 7'S3-3 : &SCf v, tt, BulBgS tt 
S^^tS-C*tltf^Sma5l80 f - £ < z , , v< >£J| 

it^gg3oo tcafiH§5oo SriiLTEtfrrs. 

Xf 9 y'S 4 : *|-HgCtt. »lt^Sa300 K.J:*)iU 

[0 03 3] Xf 9 7*S4-i: SSfHgCtt, ftg#a><=> 
g{f§P360 (CfcOtSJIf-f <z, , y,>££fIU 
$11310 *ffll»Ty, #&S?ffliffiz, tc#r&iEStt»S-c 

Z, = £,(*) 

*»fiS4TS*>*«OE-rSCiKJ:»)WBri. tb. £ 

tt«C e>tt. X h fBsR«5370 ICk «I'JXh 230A 

(H2C) tc. **i^ti©8aiffltt2,i-to»«v.K:- 
«©##qtt:J:9##ttW£U S^f-$<q. z ( . y, 

[ 0 0 3 4 ] Xf 7S4-2 : t^T ©&!?&, *|+^ 
C«j^{fgP380 ?:fflbriBS.g|5320 iCT ^HzXnJfigi 

x h«r^r©iaai#^e>Td'-bx*jpifiir*i4'r 

4. &«^t*iri6©8atf x h 2 4 0 B©)S^i|a) 

*tc. ^Rwr^, Atkmrn, t^»fettor*5<. xf 

7" S 5 : SM^v, tt. tS^^agloo «fc 0 fcTF© 

[ 0 0 3 5 ] X f 9 :/S5-l : S^V, tt, i££fiSPl8 
0 (C0:<3ligt#iSiS300 ©fetf.g[5320 ^Ti'-feXL, lg 
* >J X h 32QA©rtS^^f L . y X h 320ACC»*S § 

r**»**«aE8i7o rttsrs. tt. ?£tt&6 

[0036] X f if 7"S5-2 : fi^V, tt. @ 6©S^ 
ffl*fiz,*J. SMyx h320A«:^i83*i-ct»4*i=&^2 
ni7o -ct^a-rs. ^©^Siu-c. z,-€-©t©*syx 

tC^S^^^Sbrt z,=x, It, *cr)^y 

ti*ia^©t©r*4*»Msi/Tt«tt». to, 
c©^iE%i5S-ri. 0 

X f 7 S 6 : «tt#C tt. *lt#«S300 tc «fc 0 fel 
T©J:5{Cl/TH*. SO*. «H-*ff3. 
[ 0 0 3 7 ] Xf 9 7'S6-1 : SffS|5360 (CJ; fJS^# 
v, *» 6 ©^Mfflifftz, 4 S€ y, ©S«P3tef^. B^ia^IE© 
iBED*«f3EieBlrt«:awhtf. mtt^Ctt, t>»350 

tSIfflfe=x, [ t,*>6x,4»liO. «#{tS330 (C 

thru. fi«ilk 5C ^^ora^rtgv,^ 

V, = P c (X, , ksc) 
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[ 0 0 3 8 ] Xf-; 7*S6-2 : *W#C», 112 COS 

US* 1 ;* h320BiOT^-f*4it«: t q#g©&H 
7 t -^<x,,t,,y,>tcSsfU02DK:^-rj:^(C. v.^rilJjD 

» 7 S 7 : SH^v, B. SH^ggioo tc «fc rj ft 

^■raM * h 32<wjHc-f<'r©v 1 *iiijjn$ n/c*\ s 

fc&M*v,©x, iv, tffitfcLXI.>2>frZimtZ>. 
[003 9] tuts. ±.&Z7-?7S5te£B&LXi>J: 
t». IK, ^f-7 7 - S6-2CCte^^ffM^';^ r©£lt 

[0 04 0] friSO^Ii^-Ctia^V.^ftft^CCDBf 
^ltH»£c fc&oT&JtlrtSv.Srx, = | c (v, ,k, c ) £ 
Bf^bt. ftIt§Cit&Ilr-£<z, , y,>£&£©-C. 
ftit^CB. fe0*O-3<>»)H:«:tiKstep 4-2X®M<) 
Zhi£ : &ltZ9lX$>iXi>f!ktt%<DmBmv r < 
Xz i 'P<Dx 1 *'&^ffl$l.v t = p c (x, , k sc )l,C£<0'{%.mx 

•resworn jfc*is*J5cdf©tii«*#-c. 

SIlXtkM-CB. «ft^B300 ASftPSLfcWi^ 
©ft f t* X ^ V a - ;b jf V) £5S7 T * & I > C i ft 5 . 

«T-ctts»ojs«-*«:j: o zti^timmz tizmnv 

[0 0 4 1 ] CCt, #ixftlt#©Hg*fM&(B3^blW 

#MS«:^S«Alfc«:L.*t>fiiu, (2<u t <u)#??£u - 
&fe©£f £„ coi^&Bf^BBDitco^rtt. m« 

El Carnal Bj|-^ (Taher ElGamal : "A public keycrypto 
system and a signature scheme based on discrete lo 
qarithms " , IEEE Transactions on Informatoin Theo 
ry, Vol.IT-31, No. 4, pp.469-472(July,1985)) ©Bf# 

B, Yuo Desmedt, Yale Frankel : "Threshold cryptos 
ystems " in Advances in Cryptology-CRYPTO'89, Lect 
ure Notes in Computer Science 435, Springer-Verla 
q, Berlin, pp. 307-315(1990) «CfB2lSttTl>.5„ 



ffl 2000-207483 
16 



m 7 \tm 2 $mm «t mm~>* r i><o±w<onmm 
?. ccommmxit, *ti*ti<Dm&gi&vx> mmm 
K4oo zftbxmm'gmA&&2oo uumzti, ttcm 

fe?§500 ZMLX 1 ooguragjifcg&sftSjSu:* 
l^iS^i|a)D-CftS*s, fltoSLhOgft «»© 
JUMKBEB300, (i = i,-,u WT^txftfff^gin? 

-SO »«!ftit^g300 1 B^T©SM^»^© 
If *«#*!HI U r x, , t, , ^©»txftlt§ 
10 8B300, "5 , Btttc j §a©#ixfttt:g£B300, B 

siir©^lxft!tifSiB 3oo, fc^-^Ma -f - $ 
x,,., i&mmoxxi i&i&ts. xoarnks-mm 
S3oo, . l icmz. mfooafstMatfmmioix, \c <t -sft-st 

ISWjc. iiffBS4oo £ilL/T&Mi£=£tBioo,#7 ; --*£ 

[0042] ji{f-> - * > *MP&t9>m%%i&100 l (0% 

0 %»txftfr*Sai300 iTS^B5ti|5]«f ft&„ 

4x,=ccv ( , *, c )ici:'oB$nitTz&t>m immmtm 
g3oo,#i4TBBt^x, *»e.!aairtSv, *a#-c*tt 

l>. Bi^->XrAiLTBtrKE©ElGama1 Bf#;&ftffl-rS 
30 m« C*i6©SI©<B©^«I*^Hakp, KStifr 5tt 

1 ^f?a> © Desmet-F rankel ©Xi; KtS $ n T t ^ h . 

[ 0 0 4 3 ] B 8 A tt&XftSHUQ, -100, *» 6 ©S^ 
; &ftM-r*^l^txftlt^B300 1 ©tg)jX?r7Kb. 
^$35310 t, leHg|J320 t. ftf+H340 i. #gf§B35 
0 i. »txfj^llg|3331 i. £ft8P360 i, g^'JX 
H / F^g|J370 i, iiSffg|l380 tSGbX^Z. 05 {C 
^U/c^ 1 *J5fetfiJ©ftft«^B300 &B»©ja-e*tt-9 

ksc^KJrOa^cn^^-^x,, t&SSL. -en^r^© 

»«tiiH-«ft«30Qi«:aiscit?*s. ^2tc. mm 
Bs^©^fxftit#^g3oa^6m#aiirtSv, 
u, sci-c**. ^2-^u^txftst§ 

«H30Qi^300i,©*h-etH*J|| j ^fxftlt^gg (2<i< 
u) it 1 &bX®8BK.mt<}:'}t l c> ^txm^Mag|533i 

6Ste0fc«#itJ|BIf s -jrx, 1 .,(C»0. ^KSffiBk 

!C( ^oti^ix„ = p c ,(x„., , k, e ,)tc«toa 

50 -!fd3p B 1r-*x, ( *ti**a©»t«Rtt#J| 
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■300,. , Ki*{tT£„ fcfc-u m&®&mttm 
§300, vummx, . = o » ex, , , it t . )lc j; o x, . 
tfttmaw*?* asms* = Xl . a t r» & c a 

**c*. *©»»rts* *n l ^tJHst^gsoo, Kg 

[ o o 4 4 j c<D*zmm*svtzm<D*a*ifi 

v, l ftftftttgia^cxi -c*« t>©± 

fs. c<om2mmmi,tmimmm<D^fy^s6, s 
sa©&-c*£„ 

xf ^ S6: ^fWWtlK, (i=i,...,u) «. at* 
*it*Ht«3oo, KJ: o . WTOi^tcLrait^fJ. 
[ 0 0 4 5 ] X f v 7-S6-1 : m 1 #flftftfti&S30Cl 
tt. SftH^ggioo, (i=l,-,-0A^©t9:SlT-i?< 
z. , v, >*©z, =x, 1 1, £#gigfl350 TBf^x, i * ^ tf 
CC^gfb. »*IB««l%ci*fi6-5r»|«I^ftlffla533o 

*i = Pc. (x, , k 5CJ ) 

ifc»it#ga30Q, 

[0046] «tbi*ic. a j ^ftiigf^a^Bs 

i-l^-txait^gsoo,^ ^eoa-^^RBr- £x, , , 

k»u »tttw»k, t1 *^o-r»txa#Masi5 1 33o l «: 

Xh = Pci (x, , k 5c1 .,) 

[ 0 0 4 7 ] ««©»U»f«l9t««iB3O0i, tt. STu-i 

tfi»«kic.*«['or^fta-fA!ia8iJ33o (c«t v&mim 

Vt =x,,= p c „ (x, , k 5CU ) 

S3oo„ttf#e,tifci9:^g*s^-c«:c^^s-rs. 
[ 0 0 4 8 ] X r 9 7-S6-2 : 0 U#tx*ltgQ tt° ft 

Step?: &K*v,t2. «OI««aMft{Cj:»)»u»ft < 

*tf^a 3oo„ ©JSf^io^c i^itsrs. 
lx*ft^gg3oa «c te <,> r &m*3 § Vl *sf# p, n & cov . 

M3HJSM 

■T. C©^»«Ttt. «93R«»aiOO I (i=i 1 ...,-ott^ 

■c©^ftx«st#«a3oo,-3oa«:jifigg5oo fciiorjg 5 < 
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t ©#tx*ft#^g30Q,-~30CUCj§{i-f &ft^gi| 

aioo,svispgffi^a2co ©fit^ttmi sj>'»2^ 
fowomstmcv&z. 

[ 0 0 5 0 ] « 1 -Wu-i »ftx»St#^g300, —300, , 

©«««* j ftmntmgmsoo, x-moxm 1 0 a «c 

<2, .V, >©z, (C*tt5f«y, ©«fE*ff 9*S*«E»3I0 

«i(x. . k 5Ci ) fcj:oa#^r-^x M 43 

»a-^sffl*33i a*wu i^wif-jxH 
a*>fc 1 -p©^«x«tt#*a. c ©wrttsoa ctam-r 
^tx«it^^g3oa«iiii 0 Btc^-r.k^cc si 

0A©«^(CH(C§BttS|5320 A, ^«^g[J332 £ gj 
^340 A. BU3fx£Slf#=gg 3 001 300U^*«> 

* 'J X f- 320ACC*# iitf V X f- ^«370 i ftp 
'J* h32(M£flHRkyX h320B*Tf •feXnJtgir.S/c 

*a^^aioo iaBHittf 5as3Mr»3«) 4*^*0 
?n/c««i<c-,n»*. gatgg|J33i icasff ud&p 
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(54) {Title of invention} Electronic voting method, voting system and program recording medium 



(57) {Abstract} 

{Problem} To eliminate the need for a voter to send the key 
used to encrypt the content of the vote to a counter. 
{Solution} A voter V 4 encrypts the vote content Vj with the 
public key k PC of a counter C, associates a tag tj with the 
encrypted vote content Xj to obtain z i5 randomizes Z\ using a 
random number ri to create a preprocessed text ej, and sends a 
signature Sj for that preprocessed text and the preprocessed text 
ej to an election administrator A. The election administrator A 
creates a blind signature dj for the preprocessed text ei and 
returns it to the voter Vj. From the blind signature d j} the voter 
obtains the election administrator's signature information y x 
with the effect of the random number r { eliminated therefrom, 
and sends the vote data <z xy y ; > to the counter C. The counter C 
verifies the election administrator's signature y,-, and verification 
is successful, creates a vote list containing the data <Zj, yi> and 
discloses it to the voters. The voter Vj verifies the vote list and 
confirms that data <Zj, y;> matching his own tag tj is present in 
the list. The counter C decrypts the x { in z\ to obtain the vote 
content Vj, and counts up the number votes for the candidates. 
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{Scope of patent Claims} 

{Claim 1} An electronic voting method whereby voters obtain 
approval for a vote from an administrator and then send vote 
data to a counter device and the counter device counts the votes, 
comprising the following steps: 

(a) each voter encrypts the content of his vote for selected 
candidates by means of an encryption device using the public 
key of the counter device, randomizes information containing 
the encrypted voted content with a random number to generate a 
preprocessed text, and sends that text to the administrator 
device; 

(b) said administrator device confirms the legitimacy of each 
voter device, 

inputs the received preprocessed text into a signature generating 
device to generate a blind signature for the preprocessed text 
and returns it to the voter device; 

(c) each voter removes the effect of said random number 
component from the blind signature for the preprocessed text, 
determines the administrator signature of said administrator for 
said information containing encrypted vote content, and 
transmits that administrator signature and said information 
containing encrypted vote content as vote data to the counter 
device; 

(d) said counter decrypts said information containing encrypted 
vote content by means of a decryption device using a secret key 
corresponding to said public key to obtain the vote content, and 
counts up the votes for candidates corresponding to said vote 
content. 

{Claim 2} An electronic voting method as per Claim 1, which 
further comprises, prior to aforementioned step (d), a step (d-0) 
whereby the counter inputs the received aforesaid encrypted 
vote content and said signature information into a signature 
verification device to verify that the preprocessed text has been 
signed by said administrator, and publishes a list of information 
containing encrypted vote content, and a step (d-1) whereby said 
voter confirms that his own encrypted vote content is present in 
the list. 

{Claim 3} An electronic voting method as per Claim 1 or 2, 
wherein the step (a) of randomizing said information containing 
encrypted vote content comprises the step of generating a tag 
known only to said voter and the step of associating said tag 
with said encrypted vote content to randomize it using said 
random number; and wherein said step (d-1) comprises the step 
of separating said tag from the vote data in said list and 
verifying whether the tag is one's own. 

{Claim 4} An electronic voting method as per Claim 1 or 2, 
wherein said step (b) comprises the step of publishing a list of 
information representing voters who were given said blind 
signature as a voter list, and wherein said step (c) comprises the 
step of confirming that information representing oneself is 
contained in said voter list. 

{Claim 5} An electronic voting method as per Claim 1 or 2, 
wherein said step (d) comprises the step of publishing the results 
of counting said vote content. 

{Claim 6} An electronic voting method as per Claim 1 or 2, 
wherein, in said step (a), said voter appends voter identification 
information to said preprocessed text and transmits it to said 
administrator device; in step (b), said administrator confirms 
said voter based on said voter identification information; and in 
step (c), said voter transmits said vote data anonymously to said 
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counter device. 

{Claim 7} An electronic voting method as per Claim 1 or 2, 
wherein said step (a) comprises the step of generating a voter 
signature for said vote and transmitting it together with said vote 
to said administrator device, and wherein said step (b) 
comprises the step of verifying the authenticity of said voter 
signature for said vote. 

{Claim 8} An electronic voting method as per Claim 1, 
wherein: said counter device comprises multiple distributed 
counter devices connected in series, with each distributed 
counter device being administered by a different counter; said 
secret key is split up among said multiple distributed counter 
devices and assigned as a distributed secret key to each of them; 
in said step (c), each voter transmits said vote data to a 
distributed counter device at one end of said series; and said step 
(d) comprises the step whereby said counter devices in series 
successively perform decryption processing of said information 
containing encrypted vote content by means of a decryption unit 
with which each of them is provided, using said distributed 
secret key, and obtain said vote content by means of the final 
stage decryption processing. 

{Claim 9} An electronic voting method as per Claim 1, wherein 
said counter device comprises multiple distributed counter 
devices, with each distributed counter device being administered 
by a different counter; said secret key is split up among said 
multiple distributed counter devices and assigned as a 
distributed secret key to each of them; in said step (c), each 
voter transmits said vote data to all said distributed counter 
devices; and said step (d) comprises the step whereby said 
counter devices separately perform decryption processing of 
said encrypted vote content by means of a decryption unit with 
which each of them is provided, using said distributed secret 
key, generating intermediate decrypted data, gathering it at one 
predetermined distributed counter device, and performing 
decryption processing to obtain sate vote content. 
{Claim 10} An electronic voting method as per Claim 8 and 9, 
wherein said decryption processing is thresholded decryption 
processing whereby decryption is possible when at least a 
predetermined number of two or more of said distributed 
counter devices is operating. 

{Claim 11} An electronic voting system with multiple voter 
devices, an administrator device connected to each of said voter 
devices via a named communication channel, and {sic} 
connected to each of said voter devices via an anonymous 
communication channel, wherein 
each said voter device comprises: 

an encryption device which encrypts the vote content with the 
public key of the counter device to generate encrypted vote 
content; 

a random number generating device which generates random 
numbers; 

a randomizing device which randomizes said encrypted vote 
content with an aforesaid random number to create preprocessed 
text; 

a means which transmits said preprocessed text to said 
administrator device; 

a random number component removing device which removes 
the effect of said random number from said administrator 
device's blind signature for said preprocessed text received from 
said administrator device to find the administrator signature of 
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said administrator device for said information containing 
encrypted vote content; 

and a means which transmits said administrator signature and 
said information containing encrypted vote content to the 
counter device as vote data; 
said administrator device comprises: 

a blind signature generating device which generates a blind 
signature for said preprocessed text received; and 
a means which transmits said blind signature to voter devices; 
and said counter device comprises: 

a decryption device which decrypts said information containing 
encrypted vote content in said vote data by means of a secret 
key corresponding to said public key to obtain said vote content; 
and 

a counting device which counts up the votes for candidates 
based on said decrypted vote content. 

{Claim 12} An electronic voting system as per Claim 11, 
wherein said voter device additionally comprises an 
administrator signature verification device which verifies said 
administrator signature for said information containing 
encrypted vote content, and if the verification by the 
administrator signature verification device is successful, 
transmits said vote data to said counter device, and wherein said 
counter device comprises an administrator signature verification 
device which accepts as input said administrator signature and 
said information containing encrypted vote content in said vote 
data received from said voter device to verify said administrator 
signature. 

{Claim 13} An electronic voting system as per Claim 11, 
wherein said voter device additionally comprises a voter 
signature generating device which generates a voter signature 
for said preprocessed text and transmits its to said administrator 
device, and said administrator device comprises a voter 
signature verification device which verifies said preprocessed 
text received from each voter device and the voter signature 
thereof, and if that verification succeeds, generates said blind 
signature by means of said blind signature generating device. 
{Claim 14} An electronic voting system as per Claim 11, 
wherein said counter device comprises a vote list generating 
device which, if verification of said administrator signature is 
successful, generates a list of said vote data received from each 
said voter device as a vote list, and publishes it to make it 
accessible to said voter, and wherein said voter device 
comprises a vote list verification device which verifies whether 
or not one's own encrypted vote content is present in the vote 
list received from said counter device. 

{Claim 15} An electronic voting system as per Claim 14, 
wherein said voter device comprises a tag generating device 
which generates a tag known only to said voter, an associating 
device which associates said encrypted vote content and said tag 
to generate said information containing encrypted vote content, 
and a list verification unit which extracts said tag from each vote 
datum in said vote list and examines whether on not that tag is 
one's own in order to verify whether one's own vote data is 
contained in said vote list. 

{Claim 16} An electronic voting system as per Claim 11, 
wherein said counter device comprises multiple distributed 
counter devices connected in series, each administered by a 
different counter; said secret key is split up among said multiple 
distributed counter devices and assigned as a distributed secret 



Unexamined Patent Application Publication 2000-207483 

key to each of them; each said voter device transmits said vote 
data to a distributed counter device at one end of said series; and 
said distributed counter devices comprise decryption processing 
units which in series successively perform decryption 
processing of said information containing encrypted vote 
content using said distributed secret key which is assigned to 
each other them, and obtain said vote content by means of 
decryption processing by said decryption processing unit of said 
distributed counter device which is at the final stage. 
{Claim 17} An electronic voting system as per Claim 11, 
wherein said counter device comprises multiple distributed 
counter devices connected in series, each administered by a 
different counter; said secret key is split up among said multiple 
distributed counter devices and assigned as a distributed secret 
key to each of them; each said voter device transmits said vote 
data to all said distributed counter devices; said distributed 
counter devices each comprises a decryption processing unit, 
each of which separately performs decryption processing of said 
encrypted vote content using said distributed secret key, which 
is assigned to each of them, to generate intermediate decrypted 
data, and sends it to a predetermined one said distributed 
counter device; and said predetermined one said distributed 
counter device comprises a combination decryption unit which 
performs decryption processing of all gathered said intermediate 
decrypted data to obtain said vote content. 
{Claim 18} An electronic voting system as per Claim 16 or 17, 
wherein said decryption processing unit performs thresholded 
decryption processing whereby decryption is possible when at 
least a predetermined number of two or more of said distributed 
counter devices is operating. 

{Claim 19} In an electronic voting system which comprises 
multiple voter devices, an administrator device connected to 
each of said voter devices via a named communication channel, 
and a counter device connected to each of said voter devices via 
an anonymous communication channel, a voter device 
comprising: 

an encryption device which encrypts the vote content with the 
public key of the counter device to generate encrypted vote 
content; 

a random number generating device which generates random 
numbers; 

a randomizing device which randomizes information containing 
said encrypted vote content with an aforesaid random number to 
create preprocessed text; 

a voter signature generating device which generates a voter 
signature for said preprocessed text; 

a means which transmits said preprocessed text and its voter 
signature to the administrator device; 

a random number component removing device which accepts as 
input said random number and the administrator's blind 
signature for said preprocessed text received from said 
administrator device and removes the effect of said random 
number from said blind signature to find said administrator's 
signature for said information containing encrypted vote 
content; 

a signature verification device which accepts as input said 
administrator signature for said encrypted vote content and said 
information containing encrypted vote content and verifies said 
administrator signature; 

a means which transmits said administrator signature and said 



(4) 

information containing encrypted vote content to the counter 
device as vote data if the signature is successfully verified by 
the signature verification device; and 

a list verification device which verifies whether or not one's 
own vote data is present in the vote list received from said 
counter device. 

{Claim 20} A voter device as per Claim 19 which additionally 
comprises a tag generating device which generates a tag known 
only to said voter, and an associating device which associates 
said encrypted vote content with said tag to generate said 
information containing encrypted vote content, wherein said list 
verification part extracts said tag from each vote datum in said 
vote list received from said counter device and examines if that 
tag is one's own to verify that one's own vote data is present in 
said vote list. 

{Claim 21} In an electronic voting system which comprises 
multiple voter devices, an administrator device connected to 
each of said voter devices via a named communication channel, 
and a counter device connected to each of said voter devices via 
an anonymous communication channel, a counter device 
comprising: 

an administrator signature verification device which accepts as 
input information containing encrypted vote content encrypted 
with the public key of the counter and the administrator's 
signature for said information containing encrypted vote 
content, which are received as vote data from each said voter 
device, and verifies said administrator's signature; 
a vote list generating device which, if the verification of said 
administrator's signature is successful, generates a list of said 
vote data received from each said voter device and publishes it 
to make it accessible to said voters; 

a decryption device which decrypts said information containing 
encrypted vote content with the secret key corresponding to said 
public key to obtain the voters' vote content; and 
a counting device which counts up the votes for candidates 
based on said decrypted vote content. 

{Claim 22} A counter device as per Claim 21 which comprises 
multiple distributed counter devices connected in series, each 
administered by a different counter, wherein said secret key is 
split up among said multiple distributed counter devices and 
assigned as a distributed secret key to each of them; the vote 
data sent from each said voter device is received by a distributed 
counter device at one end of said series; said distributed counter 
devices each comprise a distributed decryption processing unit, 
which units in series successively perform decryption 
processing of said information containing encrypted vote 
content using said distributed secret key assigned to each of 
them; and said vote content is obtained by means of decryption 
processing by said distributed decryption processing unit in said 
distributed counter device which is at the final stage. 
{Claim 23} A counter device as per Claim 21 which comprises 
multiple distributed counter devices, each administered by a 
different counter, wherein said secret key is split up among said 
multiple distributed counter devices and assigned as a 
distributed secret key to each of them; each distributed counter 
device receives said vote data from all said voter devices and 
comprises a distributed decryption processing unit, each of 
which performs decryption processing of said encrypted vote 
content using said assigned distributed secret key to generated 
intermediate decrypted data, and sends it to a predetermined one 
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said distributed counter device; and said predetermined one said 
distributed counter device comprises a combination decryption 
unit which performs decryption processing of all gathered said 
intermediate decrypted data to obtain said vote content. 
{Claim 24} A counter device as per Claim 22 or 23, wherein 
said distributed decryption processing unit performs thresholded 
decryption processing whereby decryption is possible when at 
least a predetermined number of two or more of said distributed 
counter devices is operating. 

{Claim 25} A recording medium which records a program 
whereby a computer executes the processing procedure of a 
voter device in an electronic voting system which comprises 
multiple voter devices, an administrator device connected to 
each of said voter devices via a named communication channel, 
and a counter device connected to each of said voter devices via 
an anonymous communication channel, wherein said processing 
procedure comprises the following steps: 

(a) encrypting the vote content with the public key of a counter 
device to generate encrypted vote content; 

(b) generating a random number; 

(c) randomizing information containing said encrypted vote 
content with said random number to generate a preprocessed 
text; 

(d) generating a signature for said preprocessed text; 

(e) transmitting said preprocessed text and its signature to an 
election administrator device; 

(f) removing the effect of said random number from said 
administrator's blind signature for said preprocessed text 
received from the election administrator device using said 
random number to determine said administrator's signature for 
said information containing encrypted vote content; 

(g) verifying the authenticity of said information containing 
encrypted vote content; 

(h) if said verification of authenticity is successful, transmitting 
said information containing encrypted vote content and said 
administrator's signature as vote data to the counter device; and 

(i) verifying that one's own vote data is present in the vote list 
received from said counter device. 

{Claim 26} A recording medium as per Claim 25, wherein the 
processing procedure additionally comprises the step of 
generating a tag known only to said voter, and a step of 
associating said encrypted vote content and said tag to generate 
said information containing encrypted vote content, wherein 
said step (i) comprises the step of extracting said tag from each 
vote datum in said vote list received from said counter device 
and examining if that tag is one's own to verify whether one's 
own vote data is present in said vote list. 

{Claim 27} A recording medium which records a program 
whereby a computer executes the processing procedure of a 
counter device in an electronic voting system which comprises 
multiple voter devices, an administrator device connected to 
each of said voter devices via a named communication channel, 
and a counter device connected to each of said voter devices via 
an anonymous communication channel, wherein said processing 
procedure comprises the following steps: 

(a) accepting as input the information containing encrypted vote 
content encrypted with the counter's public key and the 
administrator signature for said information containing 
encrypted vote content, which are received as vote data from 
each said voter device, and verifying said administrator 
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signature; 

(b) if verification of said administrator signature is successful, 
generating a list of said vote data received from each said voter 
device as a vote list and publishing that vote list to make it 
accessible to the voters; 

(c) decrypting said information containing encrypted vote 
content using the secret key corresponding to said public key to 
obtain the voters' vote content; and 

(d) counting up the votes for candidates based on said decrypted 
vote content. 

{Claim 28} A recording medium as per Claim 27, wherein said 
counter device comprises multiple distributed counter devices 
connected in series, each administered by a different counter; 
said secret key is split up among said multiple distributed 
counter devices and assigned as a distributed secret key to each 
of them; said step (c) comprises the step of receiving said vote 
data sent from each said voter device by a distributed counter 
device at one end of said series and in series successively 
performing distributed decryption processing of said 
information containing encrypted vote content using said 
assigned distributed secret key, with said vote content being 
obtained by means of distributed decryption processing by said 
distributed decryption processing unit in said distributed counter 
device which is at the final stage. 

{Claim 29} A recording medium as per Claim 27, wherein said 
counter device comprises multiple distributed counter devices 
connected in series, each administered by a different counter; 
said secret key is split up among said multiple distributed 
counter devices and assigned as a distributed secret key to each 
of them; and said step (c) comprises the step of receiving said 
vote data from all said voter devices at each distributed counter 
device, performing decryption processing of said encrypted vote 
content using said assigned distributed secret key to generate 
intermediate decrypted data, and sending it to a predetermined 
one said distributed counter device, whereby said one 
predetermined said distributed counter device performs 
combination decryption processing of all gathered said 
intermediate decrypted data to obtain said vote content. 
{Claim 30} A recording medium as per Claim 28 or 29, wherein 
said step (c) performs thresholded distributed decryption 
processing whereby decryption is possible when at least a 
predetermined number of two or more of said distributed 
counter devices is operating. 
{Detailed description of the invention} 
{0001} 

{Technical field of the invention} This invention relates to 
electronic voting systems, voting methods and program 
recording media intended to implement secure anonymous 
voting in cases of conducting questionnaires and the like via an 
electronic communication system. 
{0002} 

{Prior art} Voting is a process whereby each voter selects a 
predetermined number (one or more) of candidates from among 
multiple candidates presented to all the eligible voters and 
provides the results of that selection to a counter, who counts up 
the number of votes for each candidate. The candidates may be 
not only the names of candidates in a political election, but also 
choices in a statistical survey. Furthermore, the vote content is 
identifying information, symbols, names, items, etc. which 
represent the candidates selected by a voter. 
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{0003} Anonymous voting allows the correspondence between 
voter and vote content to be kept secret and is suited for 
protecting privacy with respect to an individual's ideas and 
beliefs, and thus can be used in electronic conferences, surveys 
conducted via duplex communication such as CATV, and so 
forth. 

{0004} In order to conduct secure anonymous voting via 
electronic communication, it is necessary to prevent voter 
impersonation, duplicate votes, leaking of vote content or the 
like due to vote content eavesdropping, etc. Electronic voting 
schemes using digital signatures have been proposed as method 
of solving these problems, and are presented for instance in 
Atsushi Fujioka, Tatsuaki Okamoto, Kazuo Ohta: "A practical 
secret voting scheme for large scale elections", in Advances in 
Cryptology-AUSCRYPT '92, Lecture Notes in computer 
Science 718, Springer-Verlag, Berlin, pp. 244-251 (1993) and 
Japanese Patent Application Publication 6-19943 (published 28 
November 1994) "Electronic voting method and apparatus". 
{0005} In this prior art method, the voter Vj encrypts the vote 
content Vj with a key k,- to create an encrypted text x { ; as 
preprocessing to obtain a blind signature therefore, xi is 
randomized with a random number r,- to generate a preprocessed 
text e { ; the voter's signature Sj is appended to the preprocessed 
text ej and it is transmitted to an election administrator A. The 
election administrator A, after authenticating the legitimacy of 
the voter Vj based on the signature s i} appends a the election 
administrator's blind signature dj to the preprocessed text e; and 
returns it to the voter. The voter Vj obtains the signature y; of the 
election administrator A for the encrypted text Xj from the blind 
signature d ( for the preprocessed text e i} and transmits it together 
with the encrypted text Xj to a counter C. The counter C 
confirms that the encrypted text xj has been signed by the 
election administrator A and publishes a summary containing 
the encrypted text x { as is. The voter Vj, if his own encrypted 
text xj has been recorded, sends the key ki used to encrypt the 
vote content Vj to the counter C, and if it has not been recorded, 
files an objection with the counter C. The counter C uses the key 
kj received from the voter to decrypt the vote content v { from the 
encrypted text x { and counts it. 
{0006} 

{Problem to be solved by the invention} However, with this 
method, the voter Vj needs to confirm that his own encrypted 
text Xj was recorded from the vote summary published after the 
voting deadline and transmit the key k { to the counter C, i.e., it is 
a system with low voter convenience. 

{0007} The purpose of this invention is to provide a convenient 
electronic voting system and method which allows objections to 
be filed without infringing on privacy and makes it possible to 
handle counter improprieties and malfunctions and which does 
not require the voter to send the key used for encryption to the 
counter after voting. 
{0008} 

{Means of solving the problem} In this invention, a voter 
encrypts the vote content with the public key of a counter, 
further randomizes that encrypted vote content with a random 
number to generate preprocessed text, attaches a signature to 
that preprocessed text and transmits it to an election 
administrator. The election administrator, after authenticating 
the legitimacy of the voter using the attached signature, makes a 
blind signature to the preprocessed text and returns the blind 
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signature for the preprocessed text to each voter. The voter 
removes the effect of the random number from the blind 
signature for the preprocessed text to find the election 
administrator's signature information for the encrypted vote 
content, and transmits it together with the 
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encrypted vote content as vote data to the counter. The counter, 
after confirming that the signature information for the received 
encrypted vote content has been signed by the election 
administrator, publishes the vote data. After each voter has 
confirmed that his own encrypted vote content has been 
recorded in the published vote data list, the counter uses a secret 
key kept by him to extract the vote content from the encrypted 
vote content, and counts it up. If the encrypted vote content was 
not recorded in the vote list, an objection is filed against the 
counter. Furthermore, there may also be multiple counters, each 
holding a portion of the decryption key, whereby all the vote 
content is extracted from encrypted vote content by the 
cooperation of all or a specified number of counters. 
{0009} According to this invention, in the encrypted vote 
content, the vote content is randomized with a random number, 
so the election administrator and counter cannot find the vote 
content from the randomized vote content, making it possible to 
ensure anonymity of the vote. 

{0010} Here, the decryption key is held by the counter, and the 
voter does not need to again communicate with the counter for 
the purpose of opening the ballot. 

{0011} If there are multiple counters, when vote content is 
opened through their cooperation, the fact that one is a 
legitimate voter can be indicated upon filing an objection simply 
by sending the encrypted vote content and the election 
administrator's signature. That is, even if a fraudulent person is 
present among the multiple counters, the vote content cannot be 
known unless all or a specified number of counters cooperate. 
{0012} Furthermore, since encrypted vote content goes to 
distributed counters, here as well, unless all or a specified 
number of them cooperate, the midway progress of voting 
cannot be found out while voting is still going on, making for a 
fair voting scheme. 

{0013} Moreover, in cases whether opening of votes is possible 
by the cooperation not of all but of a specified number of 
counters, even if some of the counters should be fraudulent or 
become unable to cooperate in opening votes, the vote opening 
operation can be properly carried out, so this scheme can be said 
to provide for a highly fault tolerant system. 
{0014} 

{Modes of embodiment of the invention} In the following 
embodiment examples, cases are described where this invention 
is applied to voting in a political election as an example of 
voting, but as discussed above, the voting principle envisioned 
by this invention can also be applied as is to voting in statistical 
surveys. 

Embodiment example No. 1 

Figure 1 is a drawing which shows the overall constitution of 
the voting system according to this invention. The devices 100 
of T voters Vj (i=l, - T) (called voter devices) are connected to 
the device 200 of the election administrator A (called election 
administrator device) and the device 300 of the counter C 
(called counter device) via named communication channels 400 
and anonymous communication channels 500, respectively. 
When a voter Vj transmits information via a named 
communication channel 400 to the election administrator A, 
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sender information indicating who the sender is, for example a 
name Vj or identification information ID i? is appended to the 
information transmitted, while when transmitting information 
via an anonymous communication channel to the counter C, 
sender information is not appended to the information 
transmitted. Furthermore, the counter C publishes a summary of 
vote content (vote list and polling score list), which the voters 
are all able to access. Figure 3 shows an example of the 
constitution of the voter device 100 in the voting system of 
Figure 1, Figure 4 shows an example of the constitution of an 
election administrator device 200, Figure 5 shows an example of 
the constitution of a counter device 300, and Figure 6 shows an 
example of the communication sequence in the voting system of 
this invention. Furthermore, Figure 2A illustrates an eligible 
voter list 240A possessed by the election administrator A, 
Figure 2B — a list of voters 240B given approval to vote, 
Figure 2C — a vote list 320A prepared by the counter C after 
the casting but before the counting of votes, Figure 2D — an 
example of a vote list 320A after counting, and Figure 2E — a 
polling score list 320B. 

{0015} Below, the case is described wherein a voter Vj, after 
obtaining approval to vote from the election administrator A, 
performs the voting procedure with respect to the counter C. 
{0016} The notation used in the following description is 
summarized here. 

{0017} x = £c(v,k PC ): the encryption function of counter C (x: 
encrypted text, v: vote content, k PC : the counter's public key) 
V = p c (x, k sc ): the decryption function of counter C (k sc : the 
counter's secret key) 

s = Gi(e): the signature generating function of voter Vj (s: 
signature, e: encrypted vote content) 

e = £(s): the verification function for the signature of voter Vj 
d = a A (e): the blind signature generating function of the election 
administrator A (d: blind signature) 

z = Ca(y): the verification function for the signature of the 

election administrator A (y: signature, z: ballot) 

e = co A (z, r): randomization function (r: random number) 

y = 5 A (d, r): random number component elimination function (d: 

blind signature) 

Here, the encryption function ^ c and the decryption function p c 
of the counter C are ones used in well known public key 
cryptosy stems; the counter C keeps the secret key k sc secret and 
publishes the public key k PC to the voters. Furthermore, the 
randomization function co A (z, r) for blinding (preprocessing for 
blind signing) with random number r the message m to be 
signed when the voter requests a blind signature, and the 
random number component elimination function 5 A (d, r) which 
removes the random number component r from the received 
blind signature d to extract the signature y of the election 
administrator A for the ballot z, are necessarily determined by 
the blind signature function a A used by the election 
administrator A. Such signature functions include for instance 
RSA cryptography encryption functions and decryption 
functions (Ronald Rivest, Adi Shamir, Leonard Adleman: "A 
method for obtaining digital 
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signatures and public-key cryptosystems", Communications of 
the ACM, vol. 21, No. 2, pp. 120-126 (Feb., 1978)), and details 
regarding techniques of randomization with random numbers as 
preprocessing for requesting a blind signature are described in 
David Chaum: "Security without identification: Transaction 
systems to make big brother obsolete", Communications of the 
ACM, Vol. 28, No. 10, pp. 1030-1044 (Oct., 1985). 
{0018} The voter device 100 shown in Figure 3 is constituted as 
follows. A memory 121 stores in advance the voter's 
identification information IDj and name Vj. Furthermore, data 
which is generated in the device 100 and used in subsequent 
processing is also stored in the memory 121. The encryption 
device 1 10 encrypts the vote content v { selected by the voter Vj 
(here, for instance, candidate name CNDj) with the public key 
kp C of the counter C and obtains an encrypted text Xj = £ c (vj, 
kp C ). The tag generating device 1 1 1 generates a random number 
t i5 which is used as a tag known only to voter Vj, as described 
below. The associating device 112 associates the encrypted text 
xj and the tag tj and outputs Zj = X; || tj. Hereinafter, z\ will be 
called a ballot. The random number generating device 120 
generates a random number rj. The randomization device 130 
randomizes the ballot Z\ with random number r { by means of a 
randomization function e = co A (z, r) as preprocessing for blind 
signing and generates a preprocessed text e s . The signature 
generating device 140 generates a signature Sj = Oj(ej, ID,) for 
the preprocessed text ej to indicate that it belongs to the voter Vj. 
The data <e;, Sj, IDj> is transmitted from the transmission and 
reception unit 190 via a communication line 400 to the election 
administrator device 200. The connection with the election 
administrator device 200 via the communication line 400 is 
maintained until a blind signature dj is received from the 
election administrator device 200. 

{0019} The random number component elimination device 150 
removes the random number component from the blind 
signature d { received via the transmission and reception unit 190 
from the election administrator device 200 by means of the 
random number component elimination function yi = 5 A (dj, rj) 
using the random number r i} and obtains y s as the signature of 
the election administrator A for the ballot z v The signature 
verification unit 160 examines whether or not the verification 
function Z\ = £ A (yj) holds true to verify if y x is authentic. The 
data <Zj, yj> is transmitted from the transmission and reception 
unit 180 to the counter device 300. The list inspection part 170 
accesses the counter device 300 and inspects the vote list 320A 
obtained via the transmission and reception unit 180. 
{0020} The election administrator device 200 shown in Figure 4 
has a memory 240 for recording an eligible voter list 240A 
(Figure 2 A) with identification information IDj of eligible voters 
prerecorded therein, and a voter list 240B (Figure 2B) in which 
identifications IDj of voters who have been given approval to 
vote are written; a voter verification unit 210 which checks 
whether identification information IDj received from a voter is 
on the eligible voter list; a signature verification unit 220 which 
verifies the correctness of a voter's signature Sj for the voter's 
preprocessed text ej received based whether or not the 
verification function ej = £ (Sj) holds true; a voter list generation 
unit 260 which writes legitimate voters into a specific region of 
memory 240 to generate a voter list; a signature generating 
device 230 which generates a blind signature dj = a A (ej) for the 
preprocessed text ej; and a transmission and reception unit 250 
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which performs transmission and reception of data to and from 
voter devices. 

{0021} The counter device 300, as shown in Figure 5, has a 
signature verification unit 310 which verifies the signature y, by 
checking whether of not Zj = ^(yj) holds true using the 
verification function £ A (yj) on the ballot z f and the signature y> of 
the election administrator A in the vote data <Zj, y { > received via 
the transmission and reception unit 360 from a voter device 100; 
a memory 320 which stores the vote list 320A (Figure 2C) with 
a serial number q { affixed to the vote data <Zj, y ( > by the vote list 
generating unit 370 added thereto; a separation unit 350 which 
separates the encrypted text Xj from the ballot Zj = Xj || tj; a 
decryption device 330 which decrypts Xj by means of the 
decryption function p c using the counter's secret key k sc to 
obtain v ; = p c (x i} k S c) as the vote content; and a counting device 
340 which counts up the vote content v { . Furthermore, decrypted 
vote content Vj is added to the vote data corresponding to serial 
number q of the vote list 320A stored in memory 320, as shown 
in Figure 2D. The count results are stored in memory 320 as a 
polling score list 320B of the number of votes C#h (h = 1, 2, ...) 
obtained by each candidate (CND h ; h = 1, 2, ...), as shown in 
Figure 2E. The content of the vote list 320A and polling score 
list 320B are transmitted to voter device 100 making access 
through the transmission and reception unit 380. 
{0022} Below, the voting procedure in this embodiment 
example No. 1 is described with reference to Figure 6. 
Step SI: A voter Vj performs preparation for voting using the 
voter device 100 (Figure 3) as follows. 

{0023} Step Sl-1: The voter Vj encrypts the vote content v s with 
the encryption device 1 10 using the secret key k PC of the counter 
C and the encryption function £c to generate encrypted text 
Xj = trfyu k PC ). 

Furthermore, he generates a tag tj using the tag generating 
device 1 1 1 and associates it with Xj using the associating device 
112 to obtain a ballot 

Zj - Xj || tj. 

The tag tj is for instance a random number, and only the voter Vj 
knows that it is his. 

{0024} Step SI -2: The voter Vj generates a random number t { 
using the random number generating device 120 and randomizes 
Zj with Tj using the randomization device 130 to generate 
preprocessed text 
ej = co A (Zj, rj). 

{0025} Step Sl-3: The voter Vj uses the signature generating 
device 140 to generate a signature 
Sj = Gj(ej, IDj) 

for the preprocessed text ej and the identification information 
IDj, and transmits the data <ej, Sj, IDj> from the transmission 
and reception unit 190 to the election administrator device 200. 
Step S2: The election administrator device 200 (Figure 4) 
possesses in advance the relationships between registered 
eligible voter names Vj and their identification information IDj, 
as shown in Figure 2 A, in the form of an eligible voter list 240A 
(Figure 2A), and also has a voter list 240B (Figure 2B) for 
writing in, by means of the voter list generating unit 260, the 
name Vj or identification information IDj of eligible voters 
given approval to vote. The voter list is published after 
acceptance of votes is completed; if it is permissible to publish 
the names Vj of approved voters, the voter name Vj is written in, 
while if it is being avoided that the names of voters should 
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become known, the identification information IDj is written in. 
One of these is decided upon for the voting system. In the 
description below, the identification information IDj of the voter 
Vj will be written in the voter list 240B (Figure 2B). Upon 
commencement of vote acceptance, there is nothing recorded in 
the voter list. The approval procedure by the election 
administrator device 200 is carried out as follows. 
{0026} Step S2-1: The election administrator A confirms that a 
voter is an eligible voter by checking if his identification 
information IDj is present in the eligible voter list 240A (Figure 
2 A) by means of the voting eligibility confirmation unit 210. If 
it is not, the election administrator A denies the approval. 
{0027} Step S2-2: The election administrator A checks whether 
the voter Vj has previously received approval from the election 
administrator A by examining if his ID; has already been entered 
in the voter list 240B (Figure 2B) by means of the vote 
eligibility confirmation unit 210. If the ID; has already been 
given approval, the election administrator A denies approval as 
a case of duplicate voting. 

{0028} Step S2-3: If IDj has not been entered previously, the 
election administrator verifies that s i? ej and IDj satisfy the 
following formula 

using the signature verification device 220. If verification is 
successful, the election administrator A computes, via the 
signature generating device 230, the signature dj 
dj = c A (ei), 

transmits dj from the transmission and reception unit 250 to the 
voter device 100, and adds the IDj of voter Vj to the voter list 
240B (Figure 2B) in memory 240 by means of the voter list 
generating unit 260. 

{0029} Step S2-4: After acceptance of votes has ended, the 
election administrator A publishes the voter list 240B and the 
number of voters. As for the method of publication, notice is 
given in advance to eligible voters that the voter list 240B in the 
memory 240 of the election administrator device 200 can be 
accessed via arbitrary communication channels within a 
specified period of time from a specific date. The method of 
access to this list can be implemented for instance by means of a 
predetermined telephone number. The place of publication of 
voter list 240B may also be a predetermined internet address, 
rather than inside the election administrator device 200. 
Step S3: The voter Vj generates the ballot and corresponding 
signature information using the voter device 100 (Figure 3) as 
follows. 

{0030} Step S3-1: The voter Vj inputs dj and r { into the random 
number component elimination device 150 to obtain the 
signature information yj for the ballot Zj 
Vj - 5 A (dj, rj) 

{0031} Step S3-2: The voter Vj uses the signature verification 
device 160 to confirm that yj is the signature of the election 
administrator A based on whether or not 
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Zi = (U(Yi) 

holds true. If it does not, the voter Vj Claims impropriety on the 
part of the election administrator A by presenting the data <ej 
dj>. 

{0032} Step S3-3: If said signature confirmation succeeds, the 
voter Vj transmits the data <Zj, yj> from the transmission and 
reception unit 180 to the counter device 300 via communication 
channel 500. 

Step S4: The counter C collects votes using the counter device 
300 as follows. 

{0033} Step S4-1: The counter C receives vote data <Zj, yj> 
from voters via reception unit 360 and uses the signature 
verification device 310 to confirm that y { is an authentic 
signature for the ballot Zj by verifying whether or not 

Zi = (Ufa) 

holds true. If the verification succeeds, the ballot Zj and its 
signature y { are numbered with a serial number q and entered as 
vote data <q, Zj, yj> into the voter list 23 OA (Figure 2C) by 
means of the vote list generating unit 370. 
{0034} Step S4-2: After all votes have been cast, the counter C 
publishes a vote list 3 20 A by enabling access to the memory 
320 via the transmission and reception unit 380. This vote list is 
made accessible to all voters. For the publication method, 
advance notice is given of the publication period and publication 
location, just as in the case of voter list 240B discussed above. 
Step S5: The voter Vj performs verification using the voter 
device 100 as follows. 

{0035} Steps S5-1: The voter Vj accesses the memory 320 of 
the counter device 300 by means of the transmission and 
reception unit 180, receives the content of the voter list 320A 
and verifies that the number of votes listed in the voter list 320A 
is equal to the voter list published in Step 2-4 by means of the 
list verification device 170. If it does not match, number q and 
random number r is published, and a claim of impropriety is 
filed with the election administrator A. 

{0036} Steps S5-2: Voter Vi verifies that his own ballot z s has 
been published in the voter list 320A by means of the list 
verification device 170. For the verification, one may verify 
whether z { itself is present in the list, or verify that the tag tj in z f 
= xj || tj is one's own. If it has not been published, a claim of 
impropriety on the part of the counter C is made by presenting 
the vote data <z i5 yj>. 

Step S6: The counter C opens and counts votes by means of the 
counter device 300 as follows. 

{0037} Step S6-1: After commencement of reception of ballots 
Zj and signatures yj from voters Vj using the reception unit 360, 
if there are no notices of aforesaid impropriety within a specific 
period of time, the counter C separates x { the ballot Zj = Xj || tj 
with the separation unit 350, opens the ballot with the 
decryption device 330, uses the secret key k sc to determine the 
vote content Vj based on 
Vj = p c (Xj, k sc ), 
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and verifies that the vote content Vj is a correct vote, i.e. that the 
vote content Vj comprises names or symbols representing 
candidates presented in advance. If not, it is considered to be an 
invalid vote. 

{0038} Step S6-2: The counter C counts up the vote content V; 
in the voter list of Figure 2C using the counting device 340, 
obtains the number of votes cast for each candidate, publishes 
the result as a polling score table 320B shown in Figure 2E, and 
adds Vj for the qth vote datum <Xj, tj, Vj> as shown in Figure 2D. 
The count results are appended to the vote list 320A and 
published. 

Step S7: The voter V { confirms that the operations of the counter 
C are correct by means of the voter device 100. That is, he 
confirms if all of Vj has been added to the voter list 3 20 A shown 
in Figure 2C and if it corresponds to Xj and v 4 of the voter Vj. 
{0039} The aforementioned step S5 may be omitted. 
Furthermore, the publication of the polling score list in step S6- 
2, as well as step S7, may also be omitted. 
{0040} In the embodiment described above, the voter Vj 
encrypts the vote content Vj using the encryption function £ c of 
the counter C as Xj = £c( v i, kpc) anc * sends the vote data <Zj, yj> 
to the counter C, so the counter C, if he so intends, can decrypt 
xj in Zjby means of the decryption function v { = pc(Xj, k sc ) using 
the counter's secret key k PC to obtain Vj before the vote list is 
published in Step 4-2. That is, he can obtain information such as 
the voting trend or the midway results without waiting for 
publication of the vote list and leak that information to 
particular persons before the official count results come out, 
which is undesirable with respect to the fairness of an election. 
Furthermore, in embodiment example No. 1, if the counter 
device 300 breaks down, it may not be possible to complete vote 
counting on schedule. Below, an embodiment example is 
described which improves these points by decrypting and 
counting the encrypted vote content with multiple counter 
devices administered by multiple counters. 
{0041} Here, the cryptographic functions (encryption function 
£ c and decryption function pc) of the distributed counters are 
used by means of a public key cryptography scheme, with 
decryption of the encrypted text becoming possible only when 
decryption processing for each encrypted text Xj has been 
performed with the distributed decryption keys k S ci held by all 
the distributed counters, or else there is a threshold U t (2 < U t < 
U) for the number of persons required for decryption, with 
decryption being possible when the specified number of 
threshold distributed counters comes together. Such 
cryptographic functions include for example the encryption and 
decryption functions of ElGamal cryptography (Taher ElGamal: 
"A public key cryptosystem and a signature scheme based on 
discrete logarithms", IEEE Transactions on Information Theory, 
Vol. IT-31, No. 4, pp. 46SM72 (July, 1985)); details on 
techniques of decryption by distributed decryptors and 
techniques employing a threshold are described in Yvo 
Desmedt, Yale Frankel: "Threshold cryptosystems" in Advances 
in Cryptology-CRYPTO '89, Lecture Notes in Computer 
Science 435, Springer- Verlag, Berlin, pp. 307-315 (1990). 
Embodiment example No. 2 

Figure 7 shows the overall constitution of a voting system 
according to embodiment example No. 2. In this embodiment 
example, the point that the voter devices 100 are each connected 
to an election administrator device 200 via a communication 
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channels 400 and are each connected to one counter device via a 
communication line 500 is the same as in embodiment example 
No. 1; the point of difference in constitution is that multiple 
counter devices 300j Q = 1, U; hereinafter called distributed 
counter devices) are provided, whereby the distributed counter 
device 300] performs decryption processing of the encrypted 
text Xj from all voters to generate x ih which is sent to the next 
distributed counter device 300 2 , with the jth distributed counter 
device 300j similarly performing decryption processing of the 
decryption processed data x^, received from the immediately 
preceding distributed counter device 300j_j to generate xy, and 
sending it to the next distributed counter device 300 j+1 . The vote 
content v; is first obtained through decryption processing by the 
final distributed counter device 300u. Just as in embodiment 
example No. 1, when a voter device lOOj sends data to the 
administrator device 200 via communication channel 400, the 
identification information IDj of the voter Vj is appended 
thereto, while no identification information IDj is appended 
when sending data to the distributed counter device 300] via 
communication channel 500. 

{0042} Except for the fact that the counter device 300 is made 
into distributed counter devices 300, the communication 
sequence example, the example of the constitution of each voter 
device 100j, the example of the constitution of the election 
administrator device 200, etc. are the same as before. 
Furthermore, the point that each voter uses a common public 
key k PC to encrypt the vote content Vj by means of Xj = C(vj, k PC ) 
is the same as in embodiment example No. 1; however, each of 
the counters Ci to Qj has a distributed secret key k sci , k S c2, 
kscu, a U number of which are generated from the secret key 
k S c, which are used to perform decryption processing, and the 
vote content Vj cannot be decrypted from the encrypted text x s 
by any counter device 300j alone. When the aforementioned 
ElGamal cryptography is used as the cryptosystem, such 
distributed secret keys k sci , k SC 2> k SC u can for instance be 
deterrnined such that the sum of the values of these keys will be 
equal to the value of the secret key k S c corresponding to the 
public key k PC , as indicated in the aforementioned document of 
Desmedt-Frankel. 

{0043} Figure 8 A shows the constitution of the first distributed 
counter device 300! which gathers votes from the voter devices 
100 1 to 100 T and which comprises a signature verification unit 
310, a memory 320, a counting device 340, a separation unit 
350, a distributed decryption processing unit 331, reception unit 
360, a vote list generating unit 370 and a transmission and 
reception unit 380. It differs from the counter device 300 of 
embodiment example No. 1 shown in Figure 5 in the following 
respects. First, decryption processing xj, = Pci(xi, k sci ) using 
distributed secret key k S ci is performed on encrypted text x { in 
the distributed decryption processing unit 331 to generate 
intermediate decrypted data x n , which is sent to the next 
distributed counter device 300 2 . Second, the counting device 
receives decrypted vote content v { from the final distributed 
counter device 300y and counts it. The 2 nd through the Uth 
distributed counter devices 300 2 to 300u, as shown in Figure 8B 
represented by the jth distributed counter device (2 < j < U), 
only have a distributed decryption processing unit 331, 
performing decryption processing x y = p C i(xij. u k SC i) using the 
distributed secret key k SC j on the intermediate decrypted data Xy. 
i received from the preceding distributed counter device 300j_i to 
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generate intermediate decrypted data x^, which is transmitted to 
the following distributed counter device 300j +1 . However, at the 
final distributed counter device 300u, xju can be obtained as the 
final decryption result, which is the vote content Vj = x,u, by 
means of decryption processing x ;u = pcu(Xiu-i> k S cu)> arM * ^ at 
vote content Vj is transmitted to the first distributed counter 
device 300). 

{0044} The voting procedure in this embodiment example No. 2 
will be described. In this embodiment example, the same 
procedure is performed as the procedure from step SI to Step S5 
in embodiment example No. 1. However, the vote data <z { , y { > 
from each voter device 100j is received by the first distributed 
counter device 300j. In this embodiment example No. 2, steps 
S6 and S7 of embodiment example No. 1 are modified as 
follows, U being the number of distributed counter devices. 
Step S6: Distributed counter Cj (j = 1, U) performs counting 
by means of distributed counter device 300j as follows. 
{0045} Step S6-1: The first distributed counter device 300, 
separates Z\ = X\ \\ t\ in the vote data <zj, y,> from each voter 
device 100j (i = 1, T) into encrypted text Xj and tag t, with 
the separation unit 350, performs the following decryption 
processing 
x,i = pci(Xi, k $ ci) 

by means of the distributed decryption processing unit 330 using 
the distributed secret key k S ci, obtains intermediate decrypted 
data Xjj and sends it to the next, 2nd distributed counter device 
300 2 . 

{0046} Thereafter similarly, the jth distributed counter device 
300j performs decryption processing 

Xy = pcj(xj, kscj-i) on intermediate decrypted data x^ from the 
(j-l)th distributed counter device 300j_i by means of the 
distributed decryption processing unit 330 using the distributed 
secret key ksq, and sends the obtained intermediate decrypted 
data x^ to the next, G+l)th distributed counter device 300j+i. 
{0047} The final Uth distributed counter device 300u performs 
decryption processing 

Vj = Xju = pcu(Xj, k S cu) on the intermediate decrypted data 
from the (U-l)th distributed counter device by means of the 
distributed decryption processing unit 330 using the distributed 
secret key k SC u to obtain the vote content Vj. The Uth distributed 
counter device 300u verifies whether or not the obtained vote 
content is invalid. 

{0048} Step S6-2: The Uth distributed counter C v counts the 
vote content Vj using the counting device 340, publishes the 
results thereof, and adds the vote content Vj to the vote list. 
Step 7: The voter Vj confirms that the operation of the 
distributed counter device 300u is correct by means of the voter 
device 100j. 

{0049} In this way, in embodiment example No. 2, since 
decryption processing is performed sequentially by multiple 
distributed counter devices 300j to 300u and the vote content Vj 
is obtained at the final distributed counter device 300u, no 
distributed counter alone can open votes and obtain Vj before the 
start of counting. 
Embodiment example No. 3 

Figure 9 shows the overall constitution of the voting system of 
embodiment example No. 3. In this embodiment example, each 
voter device 100 s (i = 1, T) is able to connect via 
communication lines 500 to all of the distributed counter 
devices 300! to 300 U} and sends the generated vote data <Zj, y { > 
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to all the distributed counter devices 300 , to 300^ The 
constitution of each voter device 100j and of the election 
administrator device 200 is the same as in embodiment 
examples No. 1 and No. 2. 

{0050} The constitution of the 1 st to the (U-l)th distributed 
counter device 300j to 300u-i, as shown in Figure 10A 
represented by the jth distributed counter device 300j, comprises 
a signature verification unit 310 which performs verification of 
the signature y { for Zj in the vote data received from each voter 
device 100,-, a separation unit 350 which separates the encrypted 
text Xj from Zj, and a distributed decryption processing unit 331 
which performs decryption processing = p Cj (x ; , k SC j) using 
distributed decryption key k S q on the encrypted text to 
generated intermediate decrypted data xjj, which is transmitted 
to a predetermined distributed counter device, in this example 
300u. Distributed counter device 300^ as shown in Figure 10B, 
is constituted by adding a memory 320; combination decryption 
unit 332; counting device 340; a vote list generating unit 370 
which appends a serial number q to each vote datum <Zj, yj> 
collected from preceding distributed counter devices 300!, ... , 
300u and enters it into the vote list 320A; and a transmission 
and reception unit 380 which communicates with the voter 
device 100 to make the vote list 320A and polling score list 
320B accessible. In the memory 331, a vote list 320A which 
lists the received vote data and a polling score list 320B for each 
candidate representing the results of counting are formed. The 
combination decryption unit 332 performs decryption 
processing Vj = pc(x n , x^) by means of decryption function 
p c on intermediate decrypted data x lX to x.u generated by 
distributed counter devices 300! to 300y to obtain vote content 
Vj, and supplies it to the counting device 340. The counting 
device 340 verifies the validity of the vote content v i} and if it is 
valid, adds 1 to the polling score of the corresponding 
candidates in the polling score list generated in memory 320. 
Furthermore, it adds Vj to the corresponding vote data in the vote 
list. 

{0051} In this embodiment example No. 3 as well, each 
distributed counter device cannot by itself decrypt the vote 
content Vj from the encrypted text Xj, thus ensuring fairness of 
the election. 

Modified embodiment example 1 

In embodiment examples No. 2 and No. 3, the vote content v { 
cannot be decrypted from the encrypted text Xj unless all the 
distributed counters Cj to C v cooperate. However, for instance 
by forming the distributed decryption processing unit 331 
according to the method of Desmedt-Frankel discussed above, it 
is possible to decrypt Vj from encrypted text Xj encrypted using 
public key kc with at least L (2 < L < U-l) distributed counter 
devices. An embodiment example applying this method to 
embodiment example No. 2 (Figures 7, 8A and 8B) will be 
described. 

{0052} For instance, even if one of the distributed counter 
devices 300 2 to 300u, say, 300^ break downs, the immediately 
preceding distributed counter device 300j_i avoids distributed 
counter device 300j and sends intermediate decrypted data Xjj_i 
to distributed counter device 300j +l . Distributed counter device 
300 j+1 uses distributed secret key kscj+i on the intermediate 
decrypted data Xjj., according to x ij+2 = p c ( Xi , k SC j+i) to obtain 
intermediate decrypted data x ij+1 , and can then just pass it on 
further to the following distributed counter device 300 j+2 . The 
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method of generating the distributed secret key used in this case 
is indicated for instance in the aforementioned document by 
Desmedt-Frankel. Furthermore, if the constitution of all the 
distributed counter devices 300i to 300u is made as the 
constitution shown in Figure 8A, even if the first distributed 
counter device 300i should break down, the next stage 
distributed counter device 300 2 can receive vote data <Zj, yj> 
from voter devices lOOj to 100 T instead of it, substituting in 
performing the functions of distributed counter device 300! . It 
then suffices for the last stage distributed counter device 300 y to 
transmit the vote content V; obtained through decryption 
processing to the substitute distributed counter device 300 2 . 
According to this embodiment example, vote counting can be 
performed even if any number of distributed counter devices U- 
L or less should break down. 
Modified embodiment example 2 

Similarly, by applying the method of Desmedt-Frankel to the 
distributed decryption processing unit 331 and combination 
decryption unit in embodiment example No. 3 (Figures 9, 10A 
and 10B), Vj can be decrypted so long as intermediate decrypted 
data is obtained by L or more (2 < L < U-l) distributed counter 
devices out of the distributed counter devices 300] through 
300^!. For example, if distributed counter devices 300] to 
300u_l broke down, the vote content Vj can be decrypted by 
providing the intermediate decrypted data Xiu_ L+ | to x- iU from the 
remaining distributed counter devices 300u_ L +i to 300u to the 
combination decryption unit 332 of distributed counter device 
300y and applying decryption processing v { = pcteu^,, Xj,j_ L+2 , 
Xju) thereto. The validity of the obtained vote content Vj is 
verified by the counting device 340, and if valid, 1 is added to 
the polling score of the candidates corresponding to Vj in the 
poling score list in memory 320. 

{0053} In this modified embodiment example, if the 
constitution of all the distributed counter devices 300i to 300u is 
made the same as that shown in Figure 10B, even if any number 
of distributed counter devices U-L or less should break down, 
vote counting can be performed by having a remaining one 
perform the same operation as the distributed counter device in 
Figure 10B. 

{0054} Each of the devices shown in Figures 3 to 5, 8A, 8B, 
10A and 10B are shown in terms of their functional constitution; 
each of these functions can also be implemented by providing a 
control unit to cause the operations to be performed 
successively; furthermore all or part of them can be executed by 
a computer. 
{0055} 

{Effect of the invention} As described above, in this invention, 
the vote content Vj is encrypted with the counter's public key k PC , 
so there is no need for the voter to transmit a key to the counter 
in order to encrypt the vote content. 

{0056} When there are multiple counters, the ballot opening 
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operation will not begin unless the agreement of all counters is 
obtained. 

{0057} Furthermore, when a specified number of counters can 
open ballots, the ballot opening operation can be started once 
legitimate counters come together to a certain extent, allowing 
the effect of fraudulent persons or saboteurs to be eliminated. 
{0058} Furthermore, even if a counter should tamper with the 
vote content, tampering with vote content can be detected by 
perusing the published summary of vote content. That is, when 
one's own vote was not used, it suffices to disclose the encoded 
ballot Zj and the election administrator's signature y t and claim 
impropriety. Here, if there is a certain number of fraudulent 
counters, privacy when filing an objection is guaranteed. 
{0059} Moreover, when multiple counters are provided, in this 
invention, since the vote content is transmitted encrypted, 
improprieties such as a counter leaking the midway progress to 
influence an election while ballots are being collected can be 
prevented. 

{0060} As per the above, with this invention, voter convenience 
can be improved by using the counter's encryption key, and 
furthermore, by providing multiple counters, improprieties such 
as influencing an election by leaking the midway progress can 
be resolved. 

{Brief description of the drawings} 

{Figure 1} A block diagram showing the overall constitution of 
an election system according embodiment example No. 1 of this 
invention. 

{Figure 2} A is a table showing an eligible voter list; B is a 
table showing a voter list; C is a table showing a vote list; D is a 
table showing a vote list; E is a polling score list. 
{Figure 3} A block diagram showing an example of the 
functional constitution of a voter device 100. 
{Figure 4} A block diagram showing an example of the 
functional constitution of an election administrator device 300. 
{Figure 5} A block diagram showing an example of the 
functional constitution of a counter device 400. 
{Figure 6} A diagram showing the vote processing procedure. 
{Figure 7} A block diagram showing the overall constitution of 
an election system according to embodiment example No. 2. 
{Figure 8} A is a block diagram showing an example of the 
functional constitution of distributed counter device 300j in 
Figure 7; B is a block diagram showing the functional 
constitution of distributed counter devices 300 2 to 300u in 
Figure 7. 

{Claim 9} A block diagram showing the overall constitution of 
a voting system according to embodiment example No. 3. 
{Claim 10} A is a block diagram showing the functional 
constitution of distributed counter device 300! to 300^ in 
Figure 9; B is a block diagram showing the functional 
constitution of distributed counter device 300u in Figure 9. 
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{Amendment of proceedings} 

{Submission date} 22 November 1999 (1999.11.22) 

{Amendment of proceedings 1 } 

{Title of document amended} Specification 

{Title of item amended} Claim 7 

{Method of amendment} Modification 

{Content of amendment} 



{Claim 7} 

An electronic voting method as per Claim 1 or 2, wherein said 
step (a) comprises the step of generating a voter signature for 
said preprocessed text and transmitting it together with said 
preprocessed text to said administrator device, and wherein said 
step (b) comprises the step of verifying the authenticity of said 
voter signature for said preprocessed text . 



